Configuring Ports For Ip Source Guard - Edge-Core ES3528MV2 Management Manual

Edge-core 28-port fast ethernet layer 2 switch
Table of Contents

Advertisement

Use the Security > IP Source Guard > Port Configuration page to set the
C
ONFIGURING
filtering type based on source IP address, or source IP address and MAC
P
IP
ORTS FOR
address pairs.
S
G
OURCE
UARD
IP Source Guard is used to filter traffic on an insecure port which receives
messages from outside the network or fire wall, and therefore may be
subject to traffic attacks caused by a host trying to use the IP address of a
neighbor.
CLI R
"ip source-guard" on page 921
C
OMMAND
Setting source guard mode to SIP (Source IP) or SIP-MAC (Source IP
and MAC) enables this function on the selected port. Use the SIP option
to check the VLAN ID, source IP address, and port number against all
entries in the binding table. Use the SIP-MAC option to check these
same parameters, plus the source MAC address. If no matching entry is
found, the packet is dropped.
N
OTE
When enabled, traffic is filtered based upon dynamic entries learned via
DHCP snooping (see
addresses configured in the source guard binding table.
If IP source guard is enabled, an inbound packet's IP address (SIP
option) or both its IP address and corresponding MAC address (SIP-
MAC option) will be checked against the binding table. If no matching
entry is found, the packet will be dropped.
Filtering rules are implemented as follows:
EFERENCES
U
SAGE
Multicast addresses cannot be used by IP Source Guard.
:
"IPv6 Source Guard" on page
If DHCP snooping is disabled (see
check the VLAN ID, source IP address, port number, and source
MAC address (for the SIP-MAC option). If a matching entry is found
in the binding table and the entry type is static IP source guard
binding, the packet will be forwarded.
If DHCP snooping is enabled, IP source guard will check the VLAN
ID, source IP address, port number, and source MAC address (for
the SIP-MAC option). If a matching entry is found in the binding
table and the entry type is static IP source guard binding, or
dynamic DHCP snooping binding, the packet will be forwarded.
If IP source guard if enabled on an interface for which IP source
bindings have not yet been configured (neither by static
configuration in the IP source guard binding table nor dynamically
learned from DHCP snooping), the switch will drop all IP traffic on
that port, except for DHCP packets.
– 399 –
| Security Measures
C
13
HAPTER
IPv4 Source Guard
404), or static
page
412), IP source guard will

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Es3528mv2-dc

Table of Contents